FreeBSD is actually behind Linux - it lacks an effective access control framework and did not have ASLR until the latest release. At least they're working on it (TrustedBSD, Capsicum).
FreeBSD is actually behind Linux - it lacks an effective access control framework and did not have ASLR until the latest release. At least they're working on it (TrustedBSD, Capsicum).
https://www.digitalocean.com/community/tutorials/an-introduc...
https://www.digitalocean.com/community/tutorials/an-introduc...
And here is the referenced email with a bit of context:
how many people ever bother to write and deploy a trustedbsd policy: (to first order approximation) nobody
Defaults matter, a feature matrix checkbox is simply deceptive because the fact something isn't on (and configured) by default often means its an insane amount to work to try to enable it and/or thing are unfixably broken when you do (from a user point of view)
unfortunately both these things are true of trustedBSD
LOCK System http://www.cyberdefenseagency.com/publications/LOCK-An_Histo...
Sidewinder firewall http://www.ittoday.info/AIMS/DSM/83-10-35.pdf
Flask project/architecture https://www.cs.utah.edu/flux/fluke/html/flask.html
Nonetheless, the old stuff (esp LOCK & LOCK/ix) are still stronger in security architecture and design despite all these years. Good design is timeless I guess. :)
Note: Cambridge's CHERI project and CheriBSD are the cutting-edge for FreeBSD security as they do capability-security from hardware up with FreeBSD already ported. Also supports Capsicum, Flask, and separation kernels if one wanted. True integration of each major branch of INFOSEC. :)
Fortunately, the best security approaches (HW-centric) are portable to both w/ FreeBSD getting most prototypes. You can already run capability-secure FreeBSD via Cambridge CHERI project. Criswell's people are doing lots of stuff with FreeBSD and maybe Linux:
https://www.cl.cam.ac.uk/research/security/ctsrd/cheri/
http://sva.cs.illinois.edu/pubs.html
Examples for Linux include these:
http://scholar.lib.vt.edu/theses/available/etd-10112006-2048...
https://web.archive.org/web/20120509155852/http://archives.e...
https://docs.google.com/file/d/0B1i_Zf52vJctMTA4YTI1MmUtNzdj...
That doesn't even include software-related techniques like microkernels, low TCB software, safe low-level languages, and automatic compiler transformations for security that neither are adopting. They're both low-medium assurance by my standards due to cultural refusal to apply what's proven to work. So, I already have predictions about tech-transfer of papers above to Linux/FreeBSD use at large. You can probably guess how optimistic I am. ;)